OpenAI Shuts Down Campaign to Steal AI 'Reasoning' Linked to Chinese Firm
OpenAI has identified and shut down a coordinated campaign that attempted to extract protected internal reasoning from its AI models. The company says the operators did not breach its systems or databases, but instead manipulated interactions with the models to trick them into revealing reasoning that should have stayed hidden, a technique known as adversarial distillation, where one company's model outputs are used without permission to train or improve a rival model.
OpenAI traced a core part of the activity to individuals associated with Moonshot AI, a Beijing-based AI company, though it did not share technical evidence for this attribution. The campaign began at low volume on 1 July 2026, before spiking to 16,000 suspicious requests from over 4,000 accounts on 24 and 25 July. Further investigation uncovered similar patterns across more than 15,000 users before OpenAI fully disrupted the campaign on 28 July.
OpenAI has since banned the accounts involved and deployed new safeguards, including closing a technical pathway that allowed some encrypted reasoning data to be replayed and read by those who already held it. Separately, researchers published findings in August 2026 describing a related architectural flaw that could let attackers extract reasoning traces by feeding them into weaker, less protected models from the same provider.